Practical cross-cloud detection playbook

Has anyone published a practical runbook for triaging identity‑centric alerts across AWS, Azure, and GCP? Last week we tuned alerts around unusual AssumeRole spikes and suspicious service principal logins, but I’m aiming for repeatable steps that balance speed with false‑positive control. If you’ve got a vetted example using OCSF/Sigma with GuardDuty, Defender for Cloud, or Chronicle, a pointer would help.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​​​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌⁠⁠‌​⁠‍‌​​‌‌‍​‍‌‌‌​‌‌​⁠‌‍​‍‌‌‌⁠​⁠‌​​⁠​​‌‌‌​‌‍⁠​​⁠‌⁠‌‌​‌‌​​‍‌⁠‌‍​‍​‍‌⁠⁠‌

Mapped CloudTrail, Azure Sign‑In Logs, and GCP Audit Logs to OCSF, then correlate on normalized principal_id/session in a 5–10 min window with an allowlist for CI roles and known service principals so your AssumeRole spikes and SP logins don’t drown signal. We keep GuardDuty/Defender findings as enrichment and drive triage via Sigma in the SIEM (rules from GitHub - SigmaHQ/sigma: Main Sigma Rule Repository) — want the short runbook?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‍​⁠‌‍​⁠​⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​​​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌​‌​‌⁠‌‍‌​‌⁠​​‌‌‍‍​⁠‌​‌‍‍‌‌​⁠​​⁠‌‍‌​​‌‌​‍‌‌⁠‌‌‌‍​‌‌‍‍⁠‌‌​⁠‌​‍‍​‍​‍‌⁠⁠‌